How to Use the Ideas Feature
What you need to know about Docusign Community IdeasThis guide will walk you through the process of sharing your ideas, voting on existing ideas, and...
22860
Want to shape the future of Docusign? Add your ideas for dream features and upvote others you love.
Idea Description:According to the current DocuSign JWT authentication documentation (https://developers.docusign.com/platform/auth/jwt-get-token/), the supported JWT claims include:{ "iss": "<integration_key>", "sub": "<user_id>", "aud": "account-d.docusign.com", "iat": <epoch_time>, "exp": <epoch_time+6000>, "scope": "signature impersonation" } However, the JSON Web Token (JWT) RFC 7519 specification (Section 4.1.7) defines the "jti" (JWT ID) claim, which provides a unique identifier for a token and can be used specifically to prevent replay attacks:“The 'jti' claim can be used to prevent the JWT from being replayed.”The jti value is a case-sensitive string that must be globally unique. While optional in the RFC, it is a widely adopted security enhancement in modern API authentication systems.Why This MattersIn real customer environments, JWT assertions are often passed through multiple layers—load balancers, proxies, middleware, observability layers, or logging systems. When the JWT assertion is URL-encoded and sent to the /token endpoint, these systems may log or store the full request. This creates a risk that the same assertion could be replayed to request a new access token.Given that Docusign manages extremely sensitive business data (contracts, legal records, identity information), strengthening API-level protections is essential. Replay protection is a foundational security mechanism that is often overlooked but has very high impact when compromised.Requested EnhancementPlease consider adding support for the "jti" claim in Docusign JWT validation logic: Allow developers to include a “jti” claim in their JWT assertions Docusign should validate the uniqueness of each jti within a configurable time window. Reject any /token request that attempts to reuse a previous “jti” value Ensures a strong guardrail against replay attacks. Optional logging or monitoring Log replay attempts to help customers detect possible credential leakage. Customer Value Strengthens API authentication security Reduces risk of replay attacks when assertions traverse proxies or logs Aligns Docusign more closely with industry best practices (per RFC 7519) Helps customers meet compliance requirements for high-assurance environments Provides higher protection for mission-critical contract data Builds defense-in-depth for JWT-based integrations With increasing threats in the SaaS ecosystem and the high sensitivity of contract data, adding jti support would be a significant improvement to Docusign’s API security posture. FreeLink/甫连信息🌍 DocuSign Partner | Partner Profile🌟The only DocuSign Partner globally with two Certified eSignature Technical Consultants🏆 DocuSign 2025 APAC Growth Engine Partner of the Year💡 Ranked #1 in the OG All Star category in DocuSign Community Wrapped 2024📊 DocuSign Community Leaderboard Top 5 contributor🚀 Expertise in DocuSign integrations with on-premises systems for leading enterprises across various industries🔗 Connect with me on LinkedIn: https://www.linkedin.com/in/gehengfeng📬 For business inquiries, feel free to connect via :WeChat/微信: +86 1381880287WhatsApp: +65 97796938
Idea Description:Currently, DocuSign supports two signing methods: email-based (remote) signing and embedded signing. Email signing links are valid for 48 hours and can be refreshed by recipients. Embedded signing URLs, however, expire in 5 minutes and cannot be refreshed.Some regions experience frequent issues where recipients are unable to receive DocuSign emails due to domain blocking, SMTP 550 errors, or false-positive spam filtering—often caused by large volumes of emails sent from the customer’s DocuSign account. At the same time, SMS/WhatsApp delivery in certain regions is also unreliable or completely unavailable. These limitations result in recipients being unable to access the signing ceremony at all.To solve this, we propose allowing integrators to generate a longer-lived signing URL via API, similar to the email signing link, that can be manually delivered through alternative channels (corporate messaging apps, internal systems, or verified communication tools).This link can require additional authentication factors—for example: Stronger knowledge-based authentication Additional identity verification before entering the signing ceremony Copy-link consent or audit entry confirming the delivery method Limiting link generation to high-privilege roles or API scopes This ensures signature integrity while providing a practical fallback when email/SMS delivery is not possible.Customer Value: Ensures users can still sign documents when email/SMS channels fail Reduces support cases related to blocked delivery (SMTP 550, spam filters, regional SMS issues) Prevents business delays caused by unreachable signers Increases flexibility for enterprise workflows in regions with strict email filtering Improves overall signer accessibility without compromising security FreeLink/甫连信息🌍 DocuSign Partner | Partner Profile🌟The only DocuSign Partner globally with two Certified eSignature Technical Consultants🏆 DocuSign 2025 APAC Growth Engine Partner of the Year💡 Ranked #1 in the OG All Star category in DocuSign Community Wrapped 2024📊 DocuSign Community Leaderboard Top 5 contributor🚀 Expertise in DocuSign integrations with on-premises systems for leading enterprises across various industries🔗 Connect with me on LinkedIn: https://www.linkedin.com/in/gehengfeng📬 For business inquiries, feel free to connect via :WeChat/微信: +86 1381880287WhatsApp: +65 97796938
Need to be able to turn a community question into a community idea. I have included lots of information in questions and have been told that I have to create an idea seperate. This is counter productive. Please create the option to move a question to an idea.
Scenario - Text contents are coming from Salesforce to Docusign CLM, converted to objects and written into MS Word files. Problem - If someone changes the word document, we need to update the source as well in salesforce from where it was coming. For Ex: If there is a text content “I am a Docusign Developer” coming from Salesforce to Docusign CLM, and a document has been created with a content “I am a Docusign Developer”. Someone changed the content to “I am a Docusign Designer”. We should write the changed content to Salesforce. So that, the source is updated with recent content.
As a financial institution, we face many impostors trying to orchestrate account takeovers. We are using Workflow Builder (formerly Maestro) for profile/account update workflows (without envelopes), which exposes us to risk when instances are left open with unlimited identity verification attempts and no time limit for completion.It would be best if we had expiration rules for each workflow so that we can limit the use of the workflow to a reasonable time-period. Further, we cannot retire old workflows without manually stopping all open instances, which is an entirely separate issue.Our other request would be to limit the number of attempts in IAM, or to have a way to limit the number of times that a phone number or email can be invited to the same workflow in a given time period.
We are currently using Nautilus (part of the Hyland/Fiserv) umbrella for our document retention platform.Currently, there isn’t integration with this product to route/send our documents back to upon completion of the signing process. Wondering if this has at all been discussed is a possibility. Would be more than willing to provide for more information if needed.
Enable CLM Attributes & Dynamic Variables in Reminder Email TemplatesProblemIn Docusign CLM, reminder email templates currently have a major limitation: CLM attributes cannot be added to reminder email templates When a reminder template is directly attached to an Agreement: No additional attribute values can be displayed in the reminder email No dynamic CLM variables or metadata can be merged into the message This means reminder emails are static and lack critical contract context.
The reminder to sign is set for a fixed number of days which doesn’t take into account weekends. It would be helpful to have the ability either at admin level or user level to be able to select whether the weekend should or should not be accounted for in the reminder days
Docusign should be able to trigger a date for last signature without setting a signing order. It’s frequently a headache in my law practice to set a signing order, especially when I have multiple parties and am trying to gather signatures as quickly as possible.
We have encountered an issue where an employee was unexpectedly out on leave and no delegated signer was assigned.One particular template had as a recipient this employee & the recipient settings were set as “sender can’t edit or delete the recipient”. This obviously caused some issues where the documents could not move forward, although our HR team had designated a delegate for all duties while this employee was out.The idea would be to allow only organization admins to be able to set delegations on behalf of customers given the use case mentioned above.
Need the ability to create a report to show how many clm licenses have been used vs the total licenses purchased for us.
When adding a 2nd signer, I find the color of the 1st signing block (light blue) is very similar to the 2nd color of the 2nd signing block (light aqua). Can this be changed?? It is mind numbing that a professional signing platform would use 2 colors that are so similar. Trying to backtrack through a document to figure out if I’ve double dragged the same initial block or the 2nd signer shouldn’t be this difficult…Use a DIFFERENT color; orange, purple, red … whatever… it’s a line of code. Option 2: allow the admin to choose the signer block color.
Can we have a solution to bulk correct envelopes. We have 1000s of envelopes where the signer was Mr.X and he left the company. Delegation is also not possible as his email is not active. Now its difficult to correct these envelopes one by one. Is there a solution?





Docusign Community
Code of ConductAlready have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.